cent used the word ‘cybercrime’ in the title or scope of legislative provisions.60 Rather, legislation more commonly referred to ‘computer crimes,’61 ‘electronic communications,’62 ‘information technologies,’63 or ‘high-tech crime.’64 In practice, many of these pieces of legislation created criminal offences that are included in the concept of cybercrime, such as unauthorized access to a computer system, or interference with a computer system or data. Where national legislation did specifically use cybercrime in the title of an act or section (such as ‘Cybercrime Act’), the definitional section of the legislation rarely included a definition for the word ‘cybercrime.’65 When the term ‘cybercrime’ was included as a legal definition, a common approach was to define it simply as ‘the crimes referred to in this law.’66 In a similar manner, very few international or regional legal instruments define cybercrime. Neither the Council of Europe Cybercrime Convention, the League of Arab States Convention, nor the Draft African Union Convention, for example, contain a definition of cybercrime for the purposes of the instrument. The Commonwealth of Independent States Agreement, without using the term ‘cybercrime,’67 defines an ‘offence relating to computer information’ as a ‘criminal act of which the target is computer information.’68 Similarly, the Shanghai Cooperation Organization Agreement defines ‘information offences’ as ‘the use of information resources and (or) the impact on them in the informational sphere for illegal purposes.’69 The definitional approaches apparent from national, international and regional instruments inform the method adopted by this Study. The Study does not seek to ‘define’ cybercrime per se. Rather, it identifies a list, or ‘basket’, of acts which could constitute cybercrime. This has the advantage of placing the focus on careful description of the precise conduct to be criminalized. As such, the word ‘cybercrime’ itself may be better not considered as a legal term of art.70 It is notable that this is equivalent to the approach adopted by international instruments such as the United Nations Convention against Corruption.71 This instrument does not define ‘corruption’, but rather obliges States Parties to criminalize a specific set of conduct which can be more effectively described.72 ‘Cybercrime’ is therefore best considered as a collection of acts or conduct. Describing surrounding concepts It is also instructive to examine descriptions of surrounding concepts, such as ‘computer’, ‘computer system’, ‘data’ and ‘information.’ Their meaning is inherent to understanding the objects and/or protected legal interests which cybercrime acts concern. A review of international and regional instruments shows two main approaches: (i) terminology based on ‘computer’ data or 60 61 62 63 64 65 66 67 68 69 70 71 72 Study cybercrime questionnaire. Q12. See, for example, Malaysia, Computer Crimes Act 1997; Sri Lanka, Computer Crime Act 2007; Sudan, Computer Crimes Act 2007. See, for example, Albania, Electronic Communications in the Republic of Albania, Law no. 9918 2008; France, Code des postes et des communications électroniques (version consolidée) 2012; Tonga, Communications Act 2000. See, for example, India, The Information Technology Act 2000; Saudi Arabia, IT Criminal Act 2007; Bolivarian Republic of Venezuela, Ley Especial contra los Delitos Informáticos 2001; Vietnam, Law on Information Technology 2007. See, for example, Serbia, Law on Organization and Competence of Government Authorities for Combating High-Tech Crime 2010. See, for example, Botswana, Cybercrime and Computer Related Crimes Act 2007; Bulgaria, Chapter 9, Criminal Code SG No. 92/2002; Cambodia, Draft Cybercrime Law 2012; Jamaica, Cybercrimes Act 2010; Namibia, Computer Misuse and Cybercrime Act 2003; Senegal, Law No. 2008-11 on Cybercrime 2008. See for example, Oman, Royal Decree No 12/2011 issuing the Cybercrime Law; Philippines, Cybercrime Prevention Act 2012. The original agreement is in Russian language and uses the term ‘преступление в сфере компьютерной информации’, rather than the contemporary equivalent to ‘cybercrime’: ‘киберпреступности.’ Commonwealth of Independent States Agreement, Art. 1(a). Shanghai Cooperation Organization Agreement, Annex 1. See also International Telecommunication Union, 2011. Understanding Cybercrime: A guide for Developing Countries. United Nations. 2004. Convention against Corruption. Ibid., Arts. 15 et seq. 12

Select target paragraph3